The vulnerability relies on the way WhatsApp behaves when an end user’s encryption key changes. WhatsApp, by default, trusts new encryption key broadcasted by a contact and uses it to re-encrypt undelivered messages and send them without informing the sender of the change. Signal private messenger is more secure than WhatsApp, while both use the same end-to-end encryption protocol, and even recommended by the same group of security experts who are arguing “WhatsApp has no backdoor”
Source: https://thehackernews.com/2017/01/whatsapp-backdoor-encryption.html

